In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default configuration of the QNX SDP could allow an attacker being able to reduce the entropy of the PRNG, making other blended attacks more practical by gaining control over environmental factors that influence seed generation.
References
Link | Resource |
---|---|
http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000046674 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-11-14 13:29
Updated : 2017-11-30 10:53
NVD link : CVE-2017-9371
Mitre link : CVE-2017-9371
JSON object : View
CWE
CWE-332
Insufficient Entropy in PRNG
Products Affected
blackberry
- qnx_software_development_platform